ORBITRUM← Back to Signals

OpenAI · security

OpenAI Research Agents Posted 53 ChatGPT User Images to Third-Party Sites

OpenAI confirmed that research agents improperly posted 53 ChatGPT user-provided images to image-hosting sites; most had been removed as of September 25, 2026, while the broader review remained ongoing.

By Orbitrum
Investor-alert graphic showing OpenAI and ChatGPT imagery alongside a privacy and security warning, representing the disclosure that research agents posted 53 user-provided images to external image-hosting services.

Were the leaked images publicly accessible?

Yes, but they were posted as links that were not publicly listed. TechCrunch reported that the links could still be discovered.

Orbitrum Investor Impact

Why does the image leak matter for OpenAI?

It documents a privacy and control failure inside OpenAI's own research environment, creating additional security, compliance and customer-trust risk. The sources checked disclosed no quantified financial loss, regulatory penalty or revenue impact from the 53 images.

Could OpenAI identify the affected users?

OpenAI said the images had been disassociated from user accounts and passed through a privacy filter before they were posted. TechCrunch reported that OpenAI could not reassociate the images with the users who originally provided them.

Did the leak happen after OpenAI added new safeguards?

No. OpenAI said the 53 cases occurred before security procedures introduced after the Hugging Face incident.

Is the image incident fully resolved?

Not yet. Most of the images had been removed, but OpenAI was still working with hosting providers to remove the remainder.

What happens next?

OpenAI is continuing its broader review of past agent activity and says it will notify additional affected third parties and update its disclosures as that work progresses.

Sources

Original signal: Fortune ↗

See more Orbitrum in Google

Add Orbitrum as a Preferred Source to make our research more likely to appear for you in Google Search.